Data protection
1. Data Protection at a Glance
General Information
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. Detailed information on the subject of data protection can be found in the privacy policy below.
Data Collection on this Website
Who is responsible for the data collection on this website?
The data processing on this website is carried out by the website operator. Their contact details can be found in the section “Notice on the Responsible Party” in this privacy policy.
How do we collect your data?
Some of your data is collected when you provide it to us. This may, for example, be data you enter into a contact form.
Other data is collected automatically or with your consent when you visit the website by our IT systems. This mainly includes technical data (e.g. internet browser, operating system or the time of the page request). The collection of this data takes place automatically as soon as you enter this website.
What do we use your data for?
Part of the data is collected to ensure the error-free provision of the website. Other data may be used to analyse your user behaviour.
What rights do you have regarding your data?
You have the right at any time to obtain free information about the origin, recipient and purpose of your stored personal data. You also have the right to request the rectification or deletion of this data. If you have given your consent to data processing, you may withdraw this consent at any time with effect for the future. Furthermore, you have the right, under certain circumstances, to request the restriction of the processing of your personal data. You also have the right to lodge a complaint with the competent supervisory authority.
You may contact us at any time regarding this and other questions on the subject of data protection.
Analysis Tools and Third-Party Tools
When visiting this website, your browsing behaviour may be statistically evaluated. This is done primarily with the help of analysis programs.
Detailed information on these analysis programs can be found in the following privacy policy.
2. Hosting
We host the content of our website with the following provider:
WIX
The provider is Wix.com Ltd., 40 Namal Tel Aviv St., Tel Aviv 6350671, Israel (hereinafter “WIX”).
WIX is a tool for creating and hosting websites. When you visit our website, WIX analyses user behaviour, visitor sources, visitor regions and visitor numbers. WIX stores cookies in your browser that are necessary for the presentation of the website and for ensuring security (necessary cookies).
The data collected by WIX may be stored on various servers worldwide, including in the USA.
Details can be found in the WIX privacy policy: https://www.wix.com/about/privacy
Data transfers to the USA and other third countries are, according to WIX, based on the European Commission’s Standard Contractual Clauses or comparable guarantees under Art. 46 GDPR. Details can be found here: https://www.wix.com/about/privacy-dpa-users
The use of WIX is based on Art. 6(1)(f) GDPR. We have a legitimate interest in a reliable presentation of our website. Where consent has been requested, processing is based exclusively on Art. 6(1)(a) GDPR and § 25(1) TTDSG, insofar as consent includes the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent may be withdrawn at any time.
Data Processing Agreement
We have concluded a Data Processing Agreement (DPA) with the provider mentioned above. This is a contract required under data protection law that ensures the provider processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR. Details can be found here: https://www.wix.com/about/privacy-dpa-users
3. General Notes and Mandatory Information
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data are collected. Personal data is any data with which you can be personally identified. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this happens.
We would like to point out that data transmission on the internet (e.g. communication by email) may have security gaps. Complete protection of data against access by third parties is not possible.
Notice on the Responsible Party
The party responsible for data processing on this website is:
Dr. Manuela Kummeter
Abendröte 52
68305 Mannheim
Germany
Contact
Phone: +49 (0) 621 – 17025576
Fax: +49 (0) 621 – 86429740
Email: info@machenistmindfulness.de
The responsible party is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g. names, email addresses, etc.).
Storage Period
Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for the data processing ceases to apply. If you submit a justified request for deletion or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible grounds for storing your personal data (e.g. retention periods under tax or commercial law). In the latter case, the data will be deleted once these reasons no longer apply.
General Information on the Legal Basis of Data Processing on this Website
If you have given consent to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, where special categories of data under Art. 9(1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing is also based on Art. 49(1)(a) GDPR. If you consented to the storage of cookies or access to information on your device (e.g. device fingerprinting), processing is also carried out in accordance with § 25(1) TTDSG. Consent may be withdrawn at any time.
If your data is necessary for the performance of a contract or pre-contractual measures, we process your data based on Art. 6(1)(b) GDPR. Furthermore, if processing is required to comply with a legal obligation, we process your data on the basis of Art. 6(1)(c) GDPR. Data may also be processed on the basis of our legitimate interest under Art. 6(1)(f) GDPR. The applicable legal basis in each individual case is explained in the following sections of this privacy policy.
Data Protection Officer
We have appointed a data protection officer.
Dr. Manuela Kummeter
Abendröte 52
68305 Mannheim
Germany
Contact
Phone: +49 (0) 621 – 17025576
Fax: +49 (0) 621 – 86429740
Email: info@machenistmindfulness.de
Note on Data Transfer to the USA and Other Third Countries
We use tools from companies located in the USA or in other non-secure third countries from a data protection perspective. When these tools are active, your personal data may be transferred to these third countries and processed there. We would like to point out that no level of data protection comparable to that of the EU can be guaranteed in such countries. For example, US companies are obliged to hand over personal data to security authorities without you, as the data subject, being able to take legal action against this. It can therefore not be ruled out that US authorities (e.g. intelligence services) may process, analyse and permanently store your data located on US servers for monitoring purposes. We have no influence over these processing activities.
Withdrawal of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You may withdraw consent you have already given at any time. The legality of the data processing carried out until the withdrawal remains unaffected by the withdrawal.
Right to Object to Data Collection in Special Cases and to Direct Advertising (Art. 21 GDPR)
IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA, INCLUDING PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING PURPOSES, INCLUDING PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of breaches of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement. The right to lodge a complaint is without prejudice to other administrative or judicial remedies.
Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be carried out if it is technically feasible.
Right of Access, Erasure and Rectification
Within the framework of the applicable legal provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients, the purpose of the data processing and, if applicable, a right to rectification or erasure of this data. For this purpose, as well as for further questions on the subject of personal data, you may contact us at any time.
Right to Restrict Processing
You have the right to request the restriction of processing of your personal data. You may contact us at any time for this purpose. The right to restriction of processing exists in the following cases:
-
If you contest the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request restriction of the processing of your personal data.
-
If the processing of your personal data was or is unlawful, you may request restriction of data processing instead of erasure.
-
If we no longer need your personal data but you need it for the establishment, exercise or defence of legal claims, you have the right to request restriction of the processing of your personal data instead of erasure.
-
If you have lodged an objection pursuant to Art. 21(1) GDPR, a balancing of interests between your rights and ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request restriction of the processing of your personal data.
If you have restricted the processing of your personal data, such data – apart from being stored – may only be processed with your consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or of a Member State.
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or requests you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the change in the browser’s address line from “http://” to “https://” and by the lock symbol in your browser bar.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Encrypted Payment Transactions on this Website
If, after the conclusion of a contract involving payment, there is an obligation to provide us with your payment details (e.g. account number in the case of direct debit authorisation), these data are required for payment processing.
Payment transactions using common means of payment (Visa/MasterCard, direct debit) are carried out exclusively via an encrypted SSL or TLS connection. An encrypted connection can be recognised by the change in the browser’s address line from “http://” to “https://” and by the lock symbol in your browser line.
With encrypted communication, your payment details that you transmit to us cannot be read by third parties.
4. Data Collection on this Website
Cookies
Our internet pages use so-called “cookies.” Cookies are small data packets that do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device. Session cookies are automatically deleted at the end of your visit. Persistent cookies remain stored on your device until you delete them yourself or they are automatically deleted by your web browser.
Cookies can be set by us (first-party cookies) or by third-party companies (third-party cookies). Third-party cookies allow the integration of certain services from third-party companies within websites (e.g. cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g. shopping cart function or video display). Other cookies may be used to analyse user behaviour or for advertising purposes.
Cookies that are required to carry out the electronic communication process, to provide certain functions you have requested (e.g. shopping cart function), or to optimise the website (e.g. cookies to measure web audience) are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimised provision of its services. Where consent to the storage of cookies and comparable recognition technologies has been requested, processing is based exclusively on this consent (Art. 6(1)(a) GDPR and § 25(1) TTDSG); consent can be withdrawn at any time.
You can configure your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies in certain cases or in general, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.
Where cookies are set by third-party companies or for analysis purposes, we will inform you separately in this privacy policy and, if necessary, request your consent.
The data processing is technically provided by Wix.com Ltd. Reference is therefore made to the privacy policy and the information page on the use of cookies by Wix.com: https://www.wix.com/about/privacy, https://support.wix.com/en/article/cookies-and-your-wix-site
Wix describes data protection practices concerning how Wix.com Ltd. and its affiliates worldwide, including Deviant Art, Inc., collect and use data in connection with unregistered visitors and registered users, including premium users (“visitors” or “users”), in connection with their access to and use of Wix websites (including www.wix.com and its subdomains), web applications (“Wix Apps”), mobile applications (“Mobile Apps”) and related services (collectively, the “Services”).
Some cookies are “session cookies.” Such cookies are automatically deleted after your browser session ends. Others remain on your device until you delete them. These cookies help us recognise you when you return to our website.
Cookies can be classified according to type, duration and category:
Type
-
First-party cookies: Cookies placed by Wix.com on your website.
-
Third-party cookies: Cookies placed by third parties on your website.
Duration
-
Session cookies (temporary): These cookies are deleted when you close your browser and do not collect information from your computer. They usually store information in the form of a session ID that does not personally identify the user.
-
Persistent cookies (permanent/stored): These cookies remain on your hard drive until they expire (i.e. based on their expiry date) or until you delete them. These cookies are used to collect identifying information about the user, such as web surfing behaviour or preferences for a specific site.
Wix.com uses the following cookies:
-
Session cookies: ForceFlashSite, hs, XSRF-TOKEN, SSR-caching, TS*, TS01*******, TSxxxxxxxx (x replaced by numbers/letters), TSxxxxxxxx_d (x replaced by numbers/letters).
-
Persistent cookies: smSession, svSession.
Categories
-
Strictly necessary cookies: These cookies enable visitors to view the website and are also required for security reasons.
-
Functional cookies: These cookies “remember” registered visitors/customers in order to improve their user experience.
Where cookies are necessary for the proper delivery of our web offering, the legal basis for processing is Art. 6(1)(b) GDPR. Otherwise, processing is justified under Art. 6(1)(f) GDPR, since processing is necessary to safeguard a legitimate interest of our company. Our legitimate interest lies in tailoring our web offering to the needs of our users and, through web analysis, learning more about the use of our website in order to continuously improve our offering.
When you visit our website for the first time, you will be shown a pop-up explaining cookies. As soon as you click “OK,” you consent to our use of all cookies and plug-ins described in the privacy policy, cookie settings and this cookie policy.
Server Log Files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include:
-
Browser type and version
-
Operating system used
-
Referrer URL
-
Hostname of the accessing computer
-
Time of the server request
-
IP address
This data is not merged with other data sources.
The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website. For this purpose, server log files must be collected.
Contact Form
If you send us enquiries via the contact form, your details from the enquiry form, including the contact details you provide, will be stored by us for the purpose of processing the enquiry and in the event of follow-up questions. We will not pass on this data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of the requests addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested; consent can be withdrawn at any time.
The data you enter in the contact form will remain with us until you request deletion, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your enquiry has been processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.
Enquiries by Email, Telephone or Fax
If you contact us by email, telephone or fax, your enquiry, including all personal data provided therein (name, enquiry), will be stored and processed by us for the purpose of processing your request. We will not pass on this data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of the requests addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested; consent can be withdrawn at any time.
The data you send to us via contact requests will remain with us until you ask us to delete it, withdraw your consent to storage, or the purpose for storage no longer applies (e.g. after your request has been completed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
Google Fonts (Local Hosting)
This site uses so-called Google Fonts, provided by Google, for the uniform display of fonts. The Google Fonts are installed locally. There is no connection to Google servers.
Further information on Google Fonts can be found at: https://developers.google.com/fonts/faq and in Google’s privacy policy: https://policies.google.com/privacy
Status of this Privacy Policy: 30 October 2024
